SIGN IN SIGN UP

Add read-only GitHub Issues access to agent enclaves (#55531)

* Add enclave GitHub issues handoff

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Add enclave regression tests for scope and teardown

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Clear stale enclave proxy TLS CA before startup

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Address unresolved enclave review follow-ups

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Recompile lockfiles after main merge

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

* Defer enclave MCP readiness to AWF

Classify the compiler-owned awf-enclave route as deferred during the eager gateway functionality check so AWF can attach its backend and perform bounded readiness without weakening ordinary required-server checks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Preserve enclave gateway key for host AWF

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Add enclave proxy TLS DNS SAN

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Upgrade enclave proxy to mcpg v0.4.12

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Upgrade enclave firewall to v0.28.9

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Plan pr-finisher status pass

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Sort actions-lock entries and synced pin mirrors

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Define optional PR metadata for MCP gateway

Ensure strict MCP gateway config expansion sees empty values for PR-only safe-output metadata on non-PR triggers.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Extend enclave MCP transport allowance

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Translate gateway timeout for Copilot

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Discard all workflow lockfile updates

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Discard .lock.yml updates from PR branch

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Expand enclave disclosure timing range

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5

* Plan pr-finisher pass

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Fix enclave proxy review follow-ups

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

* Add ADR draft for enclave GitHub issues access

* Apply remaining changes

Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Copilot-Session: bcc38c7d-af99-4f49-8c17-b56cbb4515c5
Copilot-Session: 55c31d17-c6b2-4c62-a7ce-654908ab8982
L
Landon Cox committed
76f6ea7c222034dcb6282848ba08935d75df1b8f
Parent: 6384d0a
Committed by GitHub <noreply@github.com> on 8/28/2026, 4:35:25 AM